FINDING · EVALUATION

Sending DNS queries to eight non-DNS IP addresses within the Chinese IP range reliably detects GFW DNS poisoning: any response indicates the censor intercepted and replied to the query, since a legitimate non-DNS server would not respond. This external vantage-point technique discovers poisoned domains without in-country volunteers or local infrastructure.

From 2017-darer-filteredwebFilteredWeb: A Framework for the Automated Search-Based Discovery of Blocked URLs · §IV-C · 2017 · Network Traffic Measurement and Analysis

Implications

Tags

censors
cn
techniques
dns-poisoningmeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.